Agree and disagree. Yes, you’re right that in many cases you have to rely on an external oracle, so a protocol can’t be fully “trustless”.
However the difference is that we can abstract away the oracle from the rest of the value transfer mechanism.
For example if we want to bet on the winner of the Super Bowl, in the old days we’d have to find a trusted third party to hold the money for us. Essentially a bookie. Finding a trusted bookie, especially one who’s licensed in multiple jurisdictions is really hard.
In contrast, we can probably find a trusted “oracle” for the Super Bowl much easier. For example AP is extremely trustworthy (largely because they’re not in the legally dodgy business of sports betting). As long as AP cryptographically signs the outcome of the game (as they do for all HTTPS served content), we now have a highly trusted oracle. We can handle all the other mechanics around betting and payoffs inside a trustless smart contract.
In fact we can take this even a step further and use multiple trusted sources in a multisig setup. The chance that AP, ESPN, NBC sports and Google all collude to lie about the Super Bowl is extremely small.
So while the oracle problem means we can’t completely eliminate the need for trust, it can drastically reduce the surface area of risk by abstracting away the informational layer from the value transference layer.